It's Friday night. Do you know where your Nostr private keys are at? Hopefully not entered into the web app that you're using. nos2x and GetAlby fix this.

Reply to this note

Please Login to reply.

Discussion

What’s wrong with webapp ?

Vulnerable to cross site scripting

Yikes

I just entered my key in coracle.social. I hope that was safe. 🙃😩

I'll say probably not? I can't even get coracle to ever load for me.

Can confirm Coracle doesn't load for me since past 2 days no matter what relay I use. Even tried my own relay. Using Firefox.

Does Damus let you find your key if you didn’t write it down the first time?

Settings top left corner

Thanks, that’s what I thought but when I tried to set up the Chrome extension it didn’t accept it as valid 🤷

You will have to HEX encode it first. Read my guide here:

I don’t know if I was being stupid but with GetAlby, I didn’t know how use my keys from here with the extension. I’m probably being stupid.. 😅

I have not used GetAlby, but I've heard from people it's very similar to nos2x. You just need to add your key to the extension in an options section and then when you go to sign into astral for example, click the button that says use public key from extension. Then sign any transaction with your key any time you want to post an comment, profile change, event, etc.

Thanks sir, I’ll investigate. Likely me being stupid. Appreciate the help!

Sir, I memorised it

I can convert my npub into hex after a couple of absinthes as well

Using nos2x.

Is it possible to remove them from a web app if you used one in the past?

the data for your extension is stored locally on some web apps. i do not know about all of them though. there's a chance that while you were using a web app w/o extension that your key was compromised because it was saved in local storage. clear you local storage and hope nothing happened while you were using that app.

Ok. Thank you. Guess I would not know until after I know. Kinda sucks. But guess that’s the game.

I thought protocol was sticky note on monitor? 👀